Rule packCONSTRUCTED
Shadow copy deletion, LSASS dumping through comsvcs, long encoded PowerShell, scheduled tasks and services in user-writable paths, WMI subscriptions and a cleared Security log. Each rule ships with the false positives it was written expecting.
T1490T1003.001T1059.001T1053.005T1543.003+2
Rule packCONSTRUCTED
Long DNS labels, scripting-engine user agents at the proxy, executables fetched from a bare IP address, and SMB leaving the network. Written for the log sources most estates already collect and rarely alert on.
T1071.004T1048.003T1071.001T1105T1187+1
Rule packCONSTRUCTED
Request-fed web shells in PHP and ASP.NET, PowerShell that decodes, executes and reaches the network in one file, ransom notes, and LSASS minidumps left on disk. Hunting rules that produce files to open, not verdicts.
T1505.003T1059.001T1027T1105T1486+1
Other shelves: IR playbooks · Artifact references · Analyst tools